WordPress security plugin

WordPress security
that makes sense.

It blocks attacks, checks the site on its own and says in plain words when something needs attention.

Installs like any plugin Easy to configure WordPress 6.2+ · PHP 8.0+

  • No slowdownScans run in the background, never while somebody is browsing.
  • Instant alertsIn your WordPress dashboard and in your inbox, the moment it happens.
  • We store no informationNo personal or site information of any kind is stored.

Almost no site is hacked through the password.

Most WordPress sites are compromised through an out-of-date plugin, or one carrying a flaw. And once those flaws are disclosed, automated attacks arrive within hours.

Each of our modules adds a different layer of security, and is switched on according to what you need.

Prevention

Cuts off anything arriving with bad intent before it reaches the site.

  • Active security (firewall) recognises automated attacks.
  • Bot blocking halts the robots that crawl the site.
  • Publish shield checks that published content carries no malicious code.

Detection

Finds what already got in, even when it left no file behind.

  • Malware scanner looks for known malicious code in plugins, themes and uploads, and isolates an infected file in one click.
  • Database scanner checks for hidden spam, redirects, administrators nobody created.
  • Integrity monitor alerts you if your files change.

Hardening

Closes WordPress's back doors.

  • Server hardening stops code from running out of uploaded files.
  • WordPress hardening hides the installed version, disables the file editor and other features.
  • Custom login URL changes the entry address to your WordPress dashboard.

Control

Defines who gets in, and keeps a record of what happened.

  • IP lists allow or block specific addresses.
  • Comment control on pages, posts and on media library attachments.
  • Scan history what was checked, when, and what came back.

Checks

Alerts on newly disclosed flaws.

  • Known vulnerabilities monitors installed plugins and themes for a published flaw.

Protected in four steps.

  1. Install

    After purchase, an email arrives with the plugin. You install it from Plugins → Add New → Upload Plugin. It requires WordPress 6.2 or later and PHP 8.0 or later.

  2. Activate

    Once installed, it asks for your licence key, which you'll find in the email. Once activated, protection starts working right away.

  3. Adjust, if needed

    Every module has its own switch to turn it on when it's needed, with a short explanation of what it does.

  4. Always protected

    Updates show up under Plugins and install in one click, or on their own if automatic updates are switched on.

These are our licences.

1 site

Single

$39.99 USD per year

33% less than paying monthly

  • One WordPress installation
  • All thirteen modules
  • Flaw alerts
Buy

Unlimited sites

Agency

$299.99 USD per year

58% less than paying monthly

  • Unlimited installations
  • All thirteen modules
  • Flaw alerts
  • Made for agencies
Buy

Prices in US dollars. 14-day money-back guarantee. Licences cover standalone installations; WordPress multisite networks are not supported in this version.

Frequently asked questions.

Will it slow the site down?

Scans run on their own, in the background, never while a visitor is loading a page.

What does the plugin do, in short?

Thirteen modules grouped by what they do. Prevention: filters malicious traffic, blocks bots and checks content as it is published. Detection: compares files against the originals and looks for injected code in files and in the database. Hardening: applies server rules, hides the WordPress version and allows the login address to be changed. Control: IP lists, comments and a history of every check. Checks: flags newly published flaws in plugins and themes.

Is it useful alongside another security plugin?

Yes, though running two traffic filters at once makes little sense. If a large one is already installed, what this adds most is the alert on newly disclosed flaws and the database scan.

Is it useful if the host already runs antivirus?

Host antivirus looks at files. A good part of what this plugin looks for lives in the database, where that antivirus does not reach: hidden spam, redirects, administrators nobody created, or scheduled tasks added without permission.

Is security knowledge needed to use it?

No. It installs, activates and starts working. The switches that could break something ship turned off and explain what they do before being enabled.

What happens when it finds something?

It reports it in the dashboard and by email, naming the file or plugin involved, with a button to isolate or delete it when that can be done safely. An isolated file is disabled, not deleted, so it can be recovered.

What are the requirements?

WordPress 6.2 or later and PHP 8.0 or later. It runs on Apache, LiteSpeed and Nginx. It needs nothing special from the host: it runs no system programs and asks for no unusual permissions. It is PHP, like WordPress.

Does it work on a multisite network?

No. This version does not support multisite networks. It can be installed separately on as many standalone installations as the licence covers.

What do you do with my site's information?

We keep none of your information on servers of our own. For the licence, Freemius — the service that handles sales and updates — receives your site's address and the email of whoever activates it. Never your visitors, your content or your security logs: scans run inside your WordPress and their results stay there.

How is it updated?

Like any plugin: when a new version is out it shows up under Plugins and installs in one click, or on its own if WordPress automatic updates are switched on.

What happens if the licence is not renewed?

The plugin keeps working and protecting the site with everything it has. What stops are new versions and support, until it is renewed. Annual and monthly licences renew on their own; the one-off licence never expires.

Is there a money-back guarantee?

Yes, 14 days. If something expected is missing, it does not work as expected, or there is a problem that cannot be solved — even one caused by another plugin or the host — the money is refunded.

Where is it downloaded?

After purchase, an email arrives with the download link and the licence key. It can also be downloaded at any time from the customer account, which also holds the invoices and licence management.

Finding out in time
is almost everything.

Most hacked sites did not have a sophisticated attack on them. They had an unpatched plugin and nobody watching.

Protect my site